漏洞描述
Nacos before version 1.4.1 is vulnerable to authentication bypass because the ConfigOpsController lets the user perform management operations like querying the database or even wiping it out. While the /data/remove endpoint is properly protected with the @Secured annotation, the /derby endpoint is not protected and can be openly accessed by unauthenticated users. These endpoints are only valid when using embedded storage (derby DB) so this issue should not affect those installations using external storage (e.g. mysql).
影响产品
修复建议
建议关注厂商安全公告,及时升级至已修复版本,并结合实际资产暴露情况采取缓解措施。
参考链接
securitylab.github.comhttps://securitylab.github.com/advisories/GHSL-2020-325_326-nacos/↗github.comhttps://github.com/alibaba/nacos/issues/4463↗github.comhttps://github.com/alibaba/nacos/pull/4517↗github.comhttps://github.com/advisories/GHSA-36hp-jr8h-556f↗nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2021-29442↗